Regarding Base Roles and Custom Roles

There are two types of roles for setting device restriction information: "Base Roles" and "Custom Roles."
"Base Roles" refer to roles provided by the Access Management System, which have usage restriction information (device management privileges and device function restriction) set by default.
"Custom Roles" refer to original roles created based on the above base roles. You can edit the device function usage restriction information according to your office environment. The device management privileges are determined by the [Base Role] setting, but the [Device Management Restriction] setting takes preference for imageRUNNER ADVANCE devices.
"Custom Role (Administrator)" is a custom role based on the [Administrator] role with [Device Management Restriction] already set, to enable easy management of imageRUNNER ADVANCE devices.
The following types of base roles and custom roles (administrator) are available. A summary of the device function restrictions and device management privileges they have are indicated below.
IMPORTANT
The device can be managed with device management privileges from the remote UI, and from the control panel of the device. For devices using the AMS, only users who have been assigned the [Administrator]/[DeviceAdmin]/[NetworkAdmin] role (or a custom role with the same settings as this role) have device management privileges to access the screen for managing the device from the remote UI. The operations possible when using the control panel to manage the device are indicated below.
For base roles and custom roles (administrator), you cannot edit the device function restrictions and device management privileges. You also cannot set application restrictions or button restrictions.
For the [GuestUser] role, you can edit the device function restrictions and set application restrictions and button restrictions. However, you cannot edit the device management privileges.
NOTE
"Device applications" refer to functions that are not included in the device, but are made available by installing them (such as MEAP applications).
Role Name
Device Function Restrictions
Device Management Privileges
[Administrator]
All functions are available.
The following keys cannot be used on the [Settings/Registration] screen:
Register Remote Device for Cascade Copy (Function Settings)
Limit New Destinations (Function Settings)
Always Add Device Signature to Send (Function Settings)
Address Book PIN (Set Destination)
[PowerUser]
All functions are available.
The following keys cannot be used on the [Settings/Registration] screen, in addition to the restrictions applied when the AMS is not used:
Register Remote Device for Cascade Copy (Function Settings)
Limit New Destinations (Function Settings)
Always Add Device Signature to Send (Function Settings)
Address Book PIN (Set Destination)
Output Report (Function Settings)
Key and Certificate List for Certificate Settings (Management Settings)
[GeneralUser]
All functions can be used except for address books and specifying destination domains.
The following keys cannot be used on the [Settings/Registration] screen, in addition to the restrictions applied when the AMS is not used:
Register Remote Device for Cascade Copy (Function Settings)
Limit New Destinations (Function Settings)
Always Add Device Signature to Send (Function Settings)
Set Destination
Output Report (Function Settings)
Key and Certificate List for Certificate Settings (Management Settings)
[LimitedUser]
Only the Copy function and Print function can be used.
However, there are restrictions on color output, one-sided output, page layout, and saving to user inboxes.
The Scan function, Store function (outputting user inbox documents), and Send function cannot be used.
No keys can be used on the [Settings/Registration] screen.
[GuestUser] (guest role)
The Copy function can be used.
However, there are restrictions on color output, one-sided output, page layout, and saving to user inboxes.
The Scan function, Store function (outputting user inbox documents), Send function, and Print function cannot be used.
Application restrictions can be set. Depending on the model of the device, you can set usage restrictions for each button on the [Main Menu] screen.
No keys can be used on the [Settings/Registration] screen.
[NetworkAdmin] (custom role (administrator))
All functions are available.
The following keys cannot be used on the [Settings/Registration] screen, in addition to the restrictions applied when the AMS is not used:
Register Remote Device for Cascade Copy (Function Settings)
Limit New Destinations (Function Settings)
Always Add Device Signature to Send (Function Settings)
Address Book PIN (Set Destination)
[DeviceAdmin] (custom role (administrator))
All functions are available.
The following keys cannot be used on the [Settings/Registration] screen, in addition to the restrictions applied when the AMS is not used:
Register Remote Device for Cascade Copy (Function Settings)
Limit New Destinations (Function Settings)
Always Add Device Signature to Send (Function Settings)
Address Book PIN (Set Destination)
IMPORTANT
If you use User Authentication as the login application when the AMS is not used, the [Settings/Registration] screen is restricted for general users (users set with a role other than [Administrator]/[DeviceAdmin]/[NetworkAdmin]). Even for administrator users, the [Settings/Registration] screen is restricted according to the device management privileges ([DeviceAdmin]/[NetworkAdmin]). When the AMS is used, the above restrictions are applied in addition to the restrictions applied when the AMS is not used.
NOTE
Depending on your device, some restrictions may not be supported.